← Vulnerability feed

Vulnerability record · CVE-2018-14623 · published 14 December 2018

CVE-2018-14623: Theforeman katello sql injection vulnerability

Theforeman · Katello

A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.

4.3 CVSS 3.0 Medium EPSS 1.4% · top 28.1% CWE-89 · SQL injectionCWE-209 · Error message information leak
4.3CVSS 3.0 base score, v2 4.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/106224 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14623 Issue TrackingThird Party Advisory
http://www.securityfocus.com/bid/106224 Third Party AdvisoryVDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14623 Issue TrackingThird Party Advisory

Track CVE-2018-14623 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-3503Theforeman katello hard-coded credentials vulnerabilityThe installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…EPSS 3.0%7.5CVE-2013-4120Theforeman katello uncontrolled resource consumption vulnerabilityKatello has a Denial of Service vulnerability in API OAuth authenticationEPSS 1.3%6.5CVE-2013-2143Katello and Red Hat Satellite missing authorization in update_rolesThe users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action. A remote authe…EPSS 48%analysed5.5CVE-2016-9595Theforeman katello link following vulnerabilityA flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla…EPSS 0.40%5.4CVE-2013-0283Theforeman katello cross-site scripting vulnerabilityKatello: Username in Notification page has cross site scriptingEPSS 0.55%5.4CVE-2013-2101Theforeman katello cross-site scripting vulnerabilityKatello has multiple XSS issues in various entitiesEPSS 0.55%5.4CVE-2018-16887Redhat satellite cross-site scripting vulnerabilityA cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locati…EPSS 1.00%4.3CVE-2017-2662Theforeman katello missing authorization vulnerabilityA flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter…EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2018-14623), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.